Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

Crypto Address-Swapping Malware Remains Active After Sality Botnet Disruption

A multinational operation on Sept. 1, 2026 disrupted the Sality botnet's ability to deliver new malware, but infected computers still carry active malware that swaps cryptocurrency addresses, leaving users vulnerable to payment redirection attacks.
4 hours ago 9 views
Crypto Address-Swapping Malware Remains Active After Sality Botnet Disruption

A Sept. 1, 2026 multinational operation disrupted the Sality botnet, cutting off its operator's ability to deliver new malicious payloads to infected computers. However, malware already installed on those devices remains active and operational, according to CrowdStrike's report.

The operation affected more than 33,000 infected machines worldwide. U.S. authorities seized Sality-linked domains, while partners in Bulgaria, Hungary, and Romania acted against additional domains.

How the Threat Persists

CrowdStrike identified EggJagger as Sality's primary payload over the preceding eight years. The tool monitors the clipboard for cryptocurrency addresses and substitutes them with destinations controlled by the malware operator, affecting both Bitcoin and Ethereum transactions.

The attack works by watching when users copy a cryptocurrency address for payment. The malware replaces it with an address controlled by the operator. Users intending to pay the correct recipient may paste the substituted address into payment forms instead, inadvertently sending funds to the attacker's destination.

Because address-swapping software operates locally on infected computers, it can continue functioning after the botnet's communication channels are disrupted. Users with confirmed infections still need to remove the malware from their devices.

Technical Details

CrowdStrike describes Sality as a file infector that attaches to executable files and spreads through network shares, removable drives, and file sharing systems. The disruption changed the peer lists that infected machines use to communicate, isolating them from the operator and inserting defender-controlled servers.

CrowdStrike recommends network operators check logs and device telemetry for UDP traffic to the lighthouse address 188.166.101[.]148 as an indicator of Sality infection. The company provides YARA detection rules for scanning running processes.

The Shadowserver Foundation is working with internet service providers and incident response teams to identify infections and support user remediation.

Market snapshot

Top cryptocurrency prices

Explore all prices
BitcoinBTC $78,375.30-1.04% EthereumETH $2,483.98-0.33% Tether USDUSDT $1.00+0.04% BNBBNB $748.80+1.21% XRPXRP $1.43+2.44% USDCUSDC $1.00+0.02% SolanaSOL $103.53-0.36% TRONTRX $0.3389+1.30% HyperliquidHYPE $84.19-1.09% ZcashZEC $1,161.50+0.38%
Prices by Coinranking. Informational only.